HPE Aruba Networking Security Advisories & CVEs
108 advisories tracked · HPE Aruba Networking Security Advisories (PSIRT) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Aruba CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Check if your Aruba device is affected
Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Aruba's recent advisories.
Official source
HPE Aruba Networking Security Advisories (PSIRT) via NVD
Aruba's PSIRT bulletin portal (arubanetworks.com) is a JavaScript app with no stable public feed, so VulniPulse ingests Aruba's CVEs from NVD. Aruba publishes under the shared HPE CNA (security-alert@hpe.com), which also covers non-networking HPE products — so this feed is filtered to the full HPE Aruba Networking portfolio: ClearPass, AOS-8 mobility controllers, AOS-10 gateways and APs, Instant APs, AOS-CX and legacy AOS-Switch, Aruba Central, Fabric Composer and EdgeConnect/Silver Peak SD-WAN. Each entry links back to the official Aruba/HPE advisory when NVD carries the reference.
Latest Aruba advisories
Medium [CVE-2026-79818] ClearPass Policy Manager: vulnerability in an API interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to circumvent existing authentication controls
A vulnerability in an API interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to obtain sensitive information from the affected system. Affected product named by the advisory: ClearPass Policy Manager (CPPM).
Medium [CVE-2026-79817] ClearPass Policy Manager: sensitive information disclosure vulnerability exists in the client software of HPE Networking ClearPass Policy Manager
A sensitive information disclosure vulnerability exists in the client software of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an attacker with local access to the affected system to obtain sensitive information. Affected product named by the advisory: ClearPass Policy Manager (CPPM).
Medium [CVE-2026-79816] ClearPass Policy Manager: vulnerability in a client interface of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a DOM-based cross-site scripting (XSS) attack against a user of the affected client interface
A vulnerability in a client interface of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a DOM-based cross-site scripting (XSS) attack against a user of the affected client interface. Successful exploitation could allow an attacker to execute arbitrary script code in a victim's browser context within the affected client interface. Affected product named by the advisory: ClearPass Policy Manager (CPPM).
Medium [CVE-2026-79815] ClearPass Policy Manager: command injection vulnerability in the OnGuard agent of ClearPass Policy Manager could allow an authenticated remote attacker to inject arbitrary commands
A command injection vulnerability in the OnGuard agent of ClearPass Policy Manager could allow an authenticated remote attacker to inject arbitrary commands. Successful exploitation could allow an attacker to execute commands with elevated privileges on the affected Windows endpoint. Affected product named by the advisory: ClearPass Policy Manager (CPPM).
Medium [CVE-2026-79814] ClearPass Policy Manager: arbitrary file write vulnerability in the ClearPass Policy Manager OnGuard agent could allow malicious users on a local instance to elevate their user privileges if certain preconditions outside of the attacker's control are met
An arbitrary file write vulnerability in the ClearPass Policy Manager OnGuard agent could allow malicious users on a local instance to elevate their user privileges if certain preconditions outside of the attacker's control are met. Successful exploitation could allow a local attacker to execute arbitrary code with elevated privileges on the affected system. Affected product named by the advisory: ClearPass Policy Manager (CPPM).
Medium [CVE-2026-79813] ClearPass: local privilege escalation vulnerability exists in the ClearPass client software
A local privilege escalation vulnerability exists in the ClearPass client software. Successful exploitation could allow a low-privileged local user to execute commands with elevated privileges on the affected system, if certain conditions outside of the attacker's control are met. Affected product named by the advisory: ClearPass Policy Manager (CPPM).
Medium [CVE-2026-79812] ClearPass Policy Manager: denial of service vulnerability exists in the OnGuard agent of HPE Networking ClearPass Policy Manager
A denial of service vulnerability exists in the OnGuard agent of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an authenticated local attacker to interrupt the normal operation of the agent service. Affected product named by the advisory: ClearPass Policy Manager (CPPM).
Medium [CVE-2026-76749] Unauthenticated Sensitive Information Disclosure in AOS-S
A sensitive information disclosure vulnerability exists in AOS-S. Successful exploitation could allow an unauthenticated remote attacker to access sensitive information. Affected product named by the advisory: AOS-Switch (AOS-S).
Medium [CVE-2026-76741] Authenticated Buffer Overflow Vulnerabilities lead to Denial-of-Service in AOS-S
Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an authenticated remote attacker to cause a denial-of-service condition on the affected system. Affected product named by the advisory: AOS-Switch (AOS-S).
Medium [CVE-2026-97258] WordPress Aruba Migration Tool plugin <= 1.0.4 - Broken Access Control vulnerability
Subscriber Broken Access Control in Aruba Migration Tool <= 1.0.4 versions.
Medium [CVE-2026-76735] Authenticated Local Sensitive Information Disclosure in HPE Networking Instant On
A sensitive information disclosure vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow an authenticated local attacker with high privileges to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Instant On, only if certain preconditions outside of the attacker's control are met.
Medium [CVE-2026-76734] Unauthenticated Memory Corruption Vulnerability leads to Denial-of-Service in HPE Networking Instant On
A memory corruption vulnerability in the affected interface of HPE Networking Instant On could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service and to access some limited information within the affected component.
Medium [CVE-2026-76733] Authenticated Denial-of-Service Vulnerability in HPE Networking Instant On API Endpoint
A denial-of-service vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which resumes without manual intervention.
Medium [CVE-2026-76732] Authenticated Local Privilege Escalation Vulnerability in a Daemon of HPE Networking Instant ON
A local privilege-escalation vulnerability has been discovered in the affected daemon of HPE Networking Instant ON. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges if certain preconditions are met outside of the attacker's control.
Medium [CVE-2026-76731] Authentication Bypass in the Captive Portal of HPE Networking Instant On
An authentication bypass vulnerability in the captive portal of HPE Networking Instant On could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain limited access to some data and to make limited changes within the affected component.
Medium [CVE-2026-76730] Improper PAPI Packet handling leads to unauthorized access in HPE Networking Instant ON APs
An authentication bypass vulnerability exists in the PAPI protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to circumvent certain existing authentication mechanisms and send unauthorized network traffic to the target device.
Medium [CVE-2026-76729] Authenticated Format String Vulnerability allows Memory Corruption in HPE Networking Instant ON API Endpoint
A format string vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to cause memory corruption with a modified input. Successful exploitation could allow an attacker to provoke a denial-of-service condition or remote code execution in the affected system function.
Medium [CVE-2026-76707] EdgeConnect: vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to view some system memory contents
A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to view some system memory contents. Successful exploitation could allow an attacker to gain insight into internal services and workflows, increasing the risk of unauthorized access and elevated privileges when combined with other vulnerabilities.
Medium [CVE-2026-76706] EdgeConnect: vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to obtain sensitive information
A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could result in the disclosure of security-relevant configuration details and security feature status, which could be used to facilitate further attacks. Affected product named by the advisory: EdgeConnect SD-WAN Gateways.
Medium [CVE-2026-76705] EdgeConnect: buffer overflow vulnerability exists in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways
A buffer overflow vulnerability exists in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with Admin privilege to execute arbitrary commands on the underlying operating system.